Originally I’ve download the signal app through playstore, but often it also get updates from Droid-ify(Fdroid client). Today its weird and I got this . Explain to me this.
On the Droid-ify the signal app is provided by: org.thoughtcrimes.securesms
The package name is correct, but signal was never on F-droid.
Do you have a third party repo that might be compromised?
To add to that:
Always check the projects’ website to see the official ways it’s distributed, before you just download it from anywhere.
Not applying for signal though, as their apk site is hidden away
Not a fan of that either, that really is unfortunate. But with a bit of common sense, a person should then ask about that, if the Play Store is not an option. It’s still not a reason to download it from a source you haven’t verified to be official
No thats absolutely a reason. Signal is 100% to blame that they have no fully FOSS code repository that could then simply be compiled by FDroid and shipped there.
Instead I have to rely on some Dude I know nothing about, Twinhelix could just as well spread Malware. But I like my updates through FDroid, I like a blob Free Signal
Call it blame, but that decision is fully within their right, and what Twinhelix does technically violates F-Droids’ guidelines. If a creator doesn’t want their app on there, F-Droid calls to respect that.
The official Signal apk updates itself, so that’s not even an issue.
If your unoffical build from a third-party gives you issues one day, you are fully responsible for that.
org.thoughtcrimes.securesms
It actually might not be, googling
"org.thoughtcrimes.securesms"
doesn’t get results.thoughtcrimes
vs.thoughtcrime
I missed that, thanks for pointing it out. The one without S is the correct one.
But that makes me wonder, how did OP not end up with two signal apps then?
how did OP not end up with two signal apps then?
by that popup blocking him from installing the wrong one?
Oh, that’s from the installer and not one of those warnings you get after opening apps. Makes sense.
Technically it’s from “Google Play Protect” that got triggered during the install but yeah.
Yes, where is that from? Its not in the repos I use.
Twinhelix is the only one compiling the app from source without proprietary blobs
And molly.im
deleted by creator
deleted by creator
Google is actually correct here for once. Signal is not offered on F-Droid, and its package name is org.thoughtcrime.securesms, not org.thoughtcrimes.securesms.
Only official places to download Signal are through the Google Play Store or their website (which self-updates).
I recommend checking the official website or the Play Store to ensure that you are downloading the latest and official version of the app.
https://www.signal.org/download/android/
The official website only links to Google Play for the Android client, even on the fairly “hidden” download page.
If the official website redirects you to the Play Store, then it is safe to download the app from there.
And to be noted, I don’t think that the Android app client for Signal is available on F-Droid.
From which (enabled) repository does the app come. Signal is not on F-Droid or Izzydroid.
I don’t know about OP, but it is available in https://thecapslock.gitlab.io/fdroid-patched-apps/fdroid/repo and https://calyxos.gitlab.io/calyx-fdroid-repo/fdroid/repo
Yes, I heard that it is in the CalyxOS repo. This seems to be a legit version.
It is but in a different repo
“This app tries to spy on your personal data”
Needless to say Google hates competition
They hate the competition.
Pretty rich coming from google
Google is like your big brother. They will beat the shit out of you. But If anyone else tries to beat you they will kick their ass.
they obviously want all the data to themselves
deleted by creator
what i get from the playstore. i notice thoughtcrime vs thoughtcrimes fyi
I think it was a typo. I checked the droidfy (fdroid) version and
It’s a fake copy of Signal
The actual package name is org.thoughtcrime.securesms, not org.thoughtcrimes.securesms
Also Google officially recommends Signal on the Android website last I checked, so I don’t see why Play Protect would flag it as malware
edit: attach screenshot of package name
edit 2: fix typo in package name (accidentally typed thoughcrime)
Thanks mate
I’m on the apk from the signal website. This showed up for me as well.
I’ll just drop this here
What is the benefit of using this instead of Signal?
You get to convince your peers once more to use a different app.
Uses the signal back end and is cross compatible
It seems you are not cross compatible with my joke. I admit, I use an obscure back end.
It’s named after a rave drug.
Hell yeah
Android tablets as linked devices is why I use it. Something Signal seems to refuse to add.
Fully foss dependencies, degoogled (doesnt require Google Play services), and further hardening to the app. And you can still keep your signal contacts since it is just a fork. Available through Accressant, fdroid, and github.
But note that you need to download the Fdroid version for the degoogled version
It has an official F-droid repo.
Also it may work as a temporary solution for those who are having signal troubles
Use molly.Im. They have a repository for F-droid.
Got something similar yesterday, but for KDE-Connect from F-Droid. Downloaded the Play Store version instead.
Either it got compromised or Google is warning you because it has a different signature than the Google play version
Yes. I had it too!
And I download directly from the website and it aelf-updates. Nothing but an annoyance.
On the Droid-ify the signal app is provided by: org.thoughtcrimes.securesms
That’s Signal.
“Thoughtcrime” shouldnt be plural at least its not on my version and for other posters on this thread
Didn’t spot that. Mine is singular…
deleted by creator
that closed source code part you mention is on the server side… the client and protocols used are fully open source and constantly peer reviewd. signal cant really “leak” your messages to anyone since they are end to end encrypted.
deleted by creator
Just get a degoogled phone…
me poor
Degoogle your existsing device